Microsoft Teams vishing attacks have emerged as a new threat, with attackers using Quick Assist and a GoGRPC backdoor to compromise Microsoft 365 environments. Zscaler researchers have uncovered a sophisticated campaign that combines social engineering, remote access tools, and a custom malware payload to establish persistent access within corporate networks.
Inside the Microsoft Teams Vishing Attack Campaign
This campaign, active between January and June 2026, leverages a multi-stage approach targeting employees in Microsoft 365 environments. Attackers initiate contact by impersonating IT support staff via Microsoft Teams, often flooding inboxes with messages to create urgency. The goal: convince users to engage in a phone conversation—commonly known as vishing (voice phishing)—to gain their trust and facilitate further compromise.
Attack Sequence and Social Engineering Tactics
The attackers employ several key steps to achieve access:
- Impersonation on Microsoft Teams: Threat actors create fake Teams accounts or compromise existing ones, sending messages that appear to originate from a company’s IT department.
- Vishing Calls: Users receive phone calls from attackers who reinforce the IT support narrative and request urgent compliance, such as resolving a non-existent technical issue.
- Quick Assist Sessions: Victims are guided to initiate a session using Microsoft’s Quick Assist tool, which allows remote desktop control.
- Malware Deployment: During the remote session, attackers deliver the GoGRPC backdoor, a Go-based malware that enables persistent remote access and command execution.
This approach combines technical and psychological manipulation, exploiting trust in familiar tools like Teams and Quick Assist. The attackers’ ability to blend inbox flooding, voice calls, and remote desktop access makes the scam particularly convincing.
Technical Details: GoGRPC Backdoor and Quick Assist Abuse
The technical core of this campaign is the deployment of the GoGRPC backdoor. Written in Go, this malware is designed for stealth and persistence. Once installed, it offers attackers several capabilities:
- Remote Command Execution: Allows adversaries to run arbitrary commands on the compromised system.
- System Reconnaissance: Collects details about the host environment, including user accounts, installed software, and network configuration.
- Persistence Mechanisms: Ensures the malware remains active after reboots or user logouts.
Quick Assist, a legitimate Microsoft tool for remote support, is central to this campaign. Attackers exploit its trust and built-in capabilities to bypass many endpoint restrictions, as users themselves authorise the session. This reduces the likelihood of triggering traditional endpoint security alerts during initial access.
Targeted Products and Victim Profile
The attack specifically targets organisations using Microsoft 365 and Microsoft Teams. All versions of Teams with external access enabled are potentially vulnerable. Quick Assist is present by default on many Windows 10 and Windows 11 installations, increasing the attack surface.
Victims are typically employees who can be pressured into believing IT support requests are genuine, especially in large, distributed organisations where remote support is common.
Timeline of the Threat Campaign
The malicious activity was first identified by Zscaler analysts, who tracked incidents from January to June 2026. The observed timeline highlights the campaign’s sustained nature and evolving tactics:
- January 2026: Initial reports of Teams-based social engineering paired with vishing incidents targeting US and UK companies.
- February–April 2026: Increase in inbox flooding and use of Quick Assist for remote access. Delivery of GoGRPC backdoor becomes consistent in observed attacks.
- May–June 2026: Evidence emerges that some accesses are resold to ransomware operators, indicating the threat actor’s role as an initial access broker.
As of June 2026, the campaign remains active, with no universal patch available due to its reliance on social engineering and legitimate remote support tools.
Current Exploitation Status and Threat Actor Motivation
The attackers appear to operate as initial access brokers, gaining footholds within organisations and selling access to ransomware groups. The use of GoGRPC backdoor facilitates both initial reconnaissance and long-term persistence, making it valuable for follow-on attacks such as data theft or ransomware deployment.
While the exploit chain relies heavily on human factors, the technical sophistication of the GoGRPC malware and the abuse of legitimate Microsoft tools elevate the risk. The campaign’s focus on Microsoft 365 environments, and its ability to bypass traditional endpoint defences, underscores the need for vigilance around remote support and external communications.
Why This Microsoft Teams Vishing Attack Matters
This attack demonstrates how well-crafted social engineering can defeat technical controls, especially when trusted platforms like Microsoft Teams and Quick Assist are abused. The campaign’s link to ransomware initial access brokers raises the stakes for affected organisations, as a single compromised workstation could lead to widespread disruption.
Immediate Steps for Organisations
- Review and restrict external access in Microsoft Teams.
- Educate users on verifying IT support requests, especially those involving Quick Assist or phone calls.
- Monitor for suspicious remote access activity and deploy endpoint detection that can spot unusual use of Quick Assist and Go-based malware.
Originally reported by cybersecuritynews.com.







